Back to skill

Security audit

Google Keep

Security checks for vulnerabilities and agentic risk

Overview

This Google Keep skill does what it says, but it stores a local Keep token and installs an unpinned Python dependency during setup.

Install only if you are comfortable giving this skill access to your Google Keep account. Use a Google App Password as documented, protect the token file, review note-changing commands before running them, and prefer a pinned or locked dependency setup for more reproducible installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
package.json:8
Finding

Automatic Installation of Unpinned Python Dependency

Content
View full analysis
=0.14.0 ``` ### Technical Analysis The npm `postinstall` lifecycle script automatically creates a Python virtual environment and installs dependencies whenever the package is installed. The `gkeepapi` dependency is specified with an open-ended lower-bound constraint rather than an exact, audited version. No lock file, upper version bound, or package hashes are provided. Consequently, pip may resolve a newer `gkeepapi` release or changed transitive dependencies that were not reviewed with this project. If an allowed dependency release or its distribution infrastructure is compromised, malicious installation hooks or runtime code can execute with the privileges of the user installing or running the package. This is a supply-chain weakness rather than evidence that the current `gkeepapi` package is malicious. ### Attack Path 1. An attacker compromises a future permitted `gkeepapi` release, one of its transitive dependencies, or the relevant package distribution channel. 2. The attacker publishes malicious package code under a version satisfying `>=0.14.0`. 3. A user installs or reinstalls this npm package. 4. npm automatically invokes the `postinstall` command. 5. pip resolves and installs the compromised dependency because the project does not pin versions or verify artifact hashes. 6. Malicious installation or runtime code executes with the installing user's privileges. 7. The malicious code can access files and data available to that user, including the Google Keep token stored under `~/.config/gkeep/token.json`. ### Impact Assessment Successful exploitation provid ...[truncated 624 chars]
Remediation
View remediation
``` 2. Generate and commit a fully resolved lock file covering all transitive Python dependencies. 3. Use hash verification, such as pip's `--require-hashes`, and record approved hashes for every installed artifact. 4. Configure installation to use an explicitly trusted package index and disable unapproved supplemental indexes to reduce dependency-confusion exposure. 5. Remove automatic pip installation from npm `postinstall` where practical. Provide an explicit setup command so dependency installation is visible and intentional. 6. Regularly review and update pinned dependencies through a controlled process that includes vulnerability scanning, provenance verification, and testing. 7. Consider installing dependencies from prebuilt, verified artifacts and rejecting unexpected source distributions that may execute build hooks. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and documents capabilities that imply shell execution, local file access, environment access, and credential/token handling, yet it declares no permissions. This creates a transparency and policy-enforcement gap: users or a host agent may invoke a skill with more authority than expected, increasing the chance of unintended filesystem access or credential exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill exposes destructive operations like delete and state-changing operations like archive without warning users about data impact, trash semantics, or recovery expectations. In an agentic context, this omission can lead to accidental modification or removal of personal notes, especially when commands are issued automatically or from ambiguous prompts.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a lower bound only (gkeepapi>=0.14.0), which allows installation of any newer version, including unexpected major or compromised releases. This weakens build reproducibility and increases supply-chain risk because future dependency changes could introduce vulnerable or malicious code without any change to this repository.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
gkeepapi>=0.14.0

Static analysis

No suspicious patterns detected.